# Filebeat Management - Output Configuration Block not saving

**URL:** <https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 18, 2018, 5:08pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380 "2018-12-18T17:08:39Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [December 18, 2018, 5:08pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/1 "2018-12-18T17:08:39Z")

</div>

Hi,

I'm using filebeat centralized management, and things are setting properly.  
But when I try to create a new beat tag with Output configuration block in Kibana UI it hanged in saving page and not saving it for me.  
I tried putting Filebeat input config block instead of output config block and it saved, so it should be the output block specifically that is not working.  
I didn't even link the tag to any filebeat yet, so it should not be a filebeat issue.

Please see below kibana logs FYI (nothing seems wrong):

> {"type":"response","@timestamp":"2018-12-18T17:06:37Z","tags":,"pid":2937,"method":"put","statusCode":400,"req":{"url":"/api/beats/tag/Output","method":"put","headers":{"host":"[ocdt70573375.office.adroot.bmogc.net:5601](http://ocdt70573375.office.adroot.bmogc.net:5601)","connection":"keep-alive","content-length":"96","origin":"[http://ocdt70573375.office.adroot.bmogc.net:5601](http://ocdt70573375.office.adroot.bmogc.net:5601)","kbn-xsrf":"6.5.3","kbn-version":"6.5.3","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.75 Safari/537.36","credentials":"same-origin","content-type":"application/json","accept":"application/json","referer":"[http://ocdt70573375.office.adroot.bmogc.net:5601/app/kibana","accept-encoding":"gzip](http://ocdt70573375.office.adroot.bmogc.net:5601/app/kibana%22,%22accept-encoding%22:%22gzip), deflate","accept-language":"en-US,en;q=0.9"},"remoteAddress":"10.0.2.2","userAgent":"10.0.2.2","referer":"[http://ocdt70573375.office.adroot.bmogc.net:5601/app/kibana"},"res":{"statusCode":400,"responseTime":43,"contentLength":9},"message":"PUT](http://ocdt70573375.office.adroot.bmogc.net:5601/app/kibana%22%7D,%22res%22:%7B%22statusCode%22:400,%22responseTime%22:43,%22contentLength%22:9%7D,%22message%22:%22PUT) /api/beats/tag/Output 400 43ms - 9.0B"}  
> {"type":"response","@timestamp":"2018-12-18T17:07:01Z","tags":,"pid":2937,"method":"get","statusCode":200,"req":{"url":"/api/beats/agent/dc6da37a-9652-47d4-9fae-083aa1bfd969/configuration?validSetting=true","method":"get","headers":{"host":"[ocdt70573375.office.adroot.bmogc.net:5601](http://ocdt70573375.office.adroot.bmogc.net:5601)","user-agent":"Go-http-client/1.1","content-length":"4","accept":"application/json","content-type":"application/json","kbn-beats-access-token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJjcmVhdGVkIjoiMjAxOC0xMi0xOFQxNjoxMjozMy40MDlaIiwicmFuZG9tSGFzaCI6IjIxMTMwMDFlZWZhYzRiNjhhYzA1OTQzNmE5MGYyZmIxIiwiaWF0IjoxNTQ1MTQ5NTUzfQ.qTS74FzrNdlkXqjdbFNPHfCxyYChTjcZ5wMHfRQGQ5c","accept-encoding":"gzip"},"remoteAddress":"10.0.2.2","userAgent":"10.0.2.2"},"res":{"statusCode":200,"responseTime":205,"contentLength":9},"message":"GET /api/beats/agent/dc6da37a-9652-47d4-9fae-083aa1bfd969/configuration?validSetting=true 200 205ms - 9.0B"}

Please help advise the mechanism behind, and the possible reason for this. Thanks.

Regards,  
Perry

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [December 27, 2018, 4:54pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/2 "2018-12-27T16:54:16Z")

</div>

Hi @bhavyarm

Would you please advise some updates?

Regards, Perry

---

<div class="post-metadata">

**Author:** ![Matthew\_Apperson](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@Matthew\_Apperson](https://discuss.elastic.co/u/Matthew_Apperson)\
**Post date:** [December 27, 2018, 5:28pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/3 "2018-12-27T17:28:26Z")

</div>

When you go to save the tag, are there any errors in your browsers console?

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [December 27, 2018, 6:55pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/4 "2018-12-27T18:55:43Z")

</div>

Hi @Matthew_Apperson

No no error prompted.

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [December 27, 2018, 7:03pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/5 "2018-12-27T19:03:30Z")

</div>

Hi @Matthew_Apperson,

Sorry, apparently below prompted.

 ![beat_config_kibana_console](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a449250ac38b280d5e9625ead9b04b504c0ba74f.png)

Please check and advise. Please let me know if you need those in text form.

Regards, Perry

---

<div class="post-metadata">

**Author:** ![Matthew\_Apperson](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@Matthew\_Apperson](https://discuss.elastic.co/u/Matthew_Apperson)\
**Post date:** [December 27, 2018, 7:55pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/6 "2018-12-27T19:55:02Z")

</div>

Ok, using your browsers dev tools, can you inspect the network request for PUT /api/beats/tag/output? We need to take a look at the response from the server. There seems to be a bug in why it's not presenting the error in the UI. The raw response should at least tell us what is wrong as far as why it won't save.

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [December 27, 2018, 8:03pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/7 "2018-12-27T20:03:36Z")

</div>

Here's the response from /api/beats/tag/output

`{"statusCode":400,"error":"Bad Request","message":"[mapper_parsing_exception] object mapping for [tag.configuration_blocks.configs.output] tried to parse field [output] as object, but found a concrete value"}`

---

<div class="post-metadata">

**Author:** ![Matthew\_Apperson](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@Matthew\_Apperson](https://discuss.elastic.co/u/Matthew_Apperson)\
**Post date:** [December 27, 2018, 8:10pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/8 "2018-12-27T20:10:45Z")

</div>

OK, and the request itself? (sorry, should have asked for that all at once)

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [December 27, 2018, 8:15pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/9 "2018-12-27T20:15:26Z")

</div>

Request Header:

```
PUT /api/beats/tag/output HTTP/1.1
Host: ocdt70573375.office.adroot.bmogc.net:5601
Connection: keep-alive
Content-Length: 101
Origin: http://ocdt70573375.office.adroot.bmogc.net:5601
kbn-xsrf: 6.5.3
kbn-version: 6.5.3
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.75 Safari/537.36
credentials: same-origin
Content-Type: application/json
Accept: application/json
Referer: http://ocdt70573375.office.adroot.bmogc.net:5601/app/kibana
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: sid=Fe26.2 **1b8a39fca2dd08605dffbcb6a98a397a3915693a7e4b123e1356f8eaf91d8697*uN_nNkUj0lHBOgcHpN0F9Q*Dq9lyipw2g94uhh1mbBhaR6BlB8vwlYd0Qf_N4LueMwF4caHkV_K8zBcE-bD6eRLHM-JISAJFCOo4nMn0HzSofmXxZOtoPbO6khogDSqnof1AX5Q2ZeOOhCXgUX2q8dW_IYbKQ0K0W3JUcg3y96obg** bf31316af8d2ce559a659620bb513caaea1552c67bd8cb6b61fabcd59834e423*JLbvvEwOlkxqDXiKWDZhnDdxgiYQqmkWBve8r7n7mRY

```

Request Payload:

`{"color":"#00b3a4","configuration_blocks":[{"type":"output","configs":[{"output":"elasticsearch"}]}]}`

---

<div class="post-metadata">

**Author:** ![Matthew\_Apperson](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@Matthew\_Apperson](https://discuss.elastic.co/u/Matthew_Apperson)\
**Post date:** [December 27, 2018, 8:25pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/10 "2018-12-27T20:25:10Z")

</div>

OK. So the issue here seems to be that at some point an output with a bad config format was pushed up. Has anyone attempted to add or edit a tag via the API in your setup? Or added an `output.elasticsearch: {...}` inside another config?

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [December 27, 2018, 8:34pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/11 "2018-12-27T20:34:38Z")

</div>

Are you referring to es cluster or the kibana or filebeat config? And how should I check this? It is my own sandbox no one will be touching this except myself.

---

<div class="post-metadata">

**Author:** ![Matthew\_Apperson](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@Matthew\_Apperson](https://discuss.elastic.co/u/Matthew_Apperson)\
**Post date:** [December 27, 2018, 9:24pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/12 "2018-12-27T21:24:55Z")

</div>

Sorry, I mean in a config block of this or another tag.

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [December 27, 2018, 9:28pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/13 "2018-12-27T21:28:50Z")

</div>

The only other tag I has was a filebeat input tag.  
Maybe there are some zombie tags on the cluster? Is there an API to show all the tags in the cluster?

---

<div class="post-metadata">

**Author:** ![Matthew\_Apperson](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@Matthew\_Apperson](https://discuss.elastic.co/u/Matthew_Apperson)\
**Post date:** [December 27, 2018, 11:26pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/14 "2018-12-27T23:26:01Z")

</div>

There would be no zombie tags. But if a tag was created in the past containing an output in the “other” field. It’s affects on this issue would continue until it has been reindexed.

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [January 2, 2019, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/15 "2019-01-02T14:25:54Z")

</div>

@Matthew_Apperson Do you mean reindexing .kibana? Or all the live indices?

---

<div class="post-metadata">

**Author:** ![Matthew\_Apperson](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@Matthew\_Apperson](https://discuss.elastic.co/u/Matthew_Apperson)\
**Post date:** [January 2, 2019, 3:13pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/16 "2019-01-02T15:13:54Z")

</div>

sorry, reindexing `.management-beats`. This is the index beats management uses

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [January 2, 2019, 3:48pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/17 "2019-01-02T15:48:18Z")

</div>

> [@Matthew\_Apperson](#):
>
> .management-beats

Thanks. Do I just DELETE the index? Do I need to restart kibana or ES?

---

<div class="post-metadata">

**Author:** ![Matthew\_Apperson](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@Matthew\_Apperson](https://discuss.elastic.co/u/Matthew_Apperson)\
**Post date:** [January 2, 2019, 4:14pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/18 "2019-01-02T16:14:19Z")

</div>

The easiest way for you to reindex is probably [https://www.elastic.co/guide/en/elasticsearch/reference/current/reindex-upgrade-inplace.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/reindex-upgrade-inplace.html)

Please note we do consider the state your cluster is in right now to be a bug. You can track the status of the fix here - [https://github.com/elastic/kibana/pull/27717](https://github.com/elastic/kibana/pull/27717)

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [January 2, 2019, 4:48pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/19 "2019-01-02T16:48:22Z")

</div>

I do not have any data at all in the cluster.  
If I just delete .management-beats will it recreate a brand new in the cluster when I used the beat configuration function?

---

<div class="post-metadata">

**Author:** ![Matthew\_Apperson](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@Matthew\_Apperson](https://discuss.elastic.co/u/Matthew_Apperson)\
**Post date:** [January 2, 2019, 4:58pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380/20 "2019-01-02T16:58:51Z")

</div>

Ah, then I believe that to be correct, yes

[Next page](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380.md?page=2)
